Skip to content
FleetDeck

Privacy Policy

Last updated 31 August 2026

FleetDeck is a remote-control tool, so it necessarily touches device identifiers and screen data. This page explains exactly what we hold, what merely passes through, and what we never store.

1.Controller

The data controller is AI Influencers LLC, 30 N Gould St Ste N, Sheridan, WY 82801, United States. Privacy contact: privacy@fleetdeck.co.

2.What we collect

Account data. Email address, password hash (bcrypt — never the password itself), your name and workspace name if you provide them, role, email-verification and password-reset tokens, and the timestamps around them.

Device data. Device name, platform, model and OS version, online status, last-seen time, enrollment code, access key, chosen relay region, and — for iPhones — the device UDID.

Pairing records. When you run the USB Bootstrapper, the iPhone's Apple pairing records are uploaded and stored so our Mac can start remote touch without a cable. These are credentials for that specific phone and are treated as secrets.

VPN metadata. If you join a phone to the FleetDeck VPN, we store the assigned Tailscale node identifier and its 100.x address, plus the time a key was issued. One-off auth keys are shown once and never stored.

Billing data. Stripe customer and subscription identifiers, plan state, seat count, invoice history and referral/cashback ledger entries. We never see or store card numbers — Stripe handles them directly.

Operational logs. Request and error logs from our hosting provider and relays, including IP address, user agent and timestamps, used for security, abuse prevention and debugging.

Waitlist data. If you join the device-rental waitlist, we store the email address you entered and the time you submitted it.

3.Screen streams: in transit, not at rest

Live screen frames and your input events travel from the device agent, through a FleetDeck relay, to your browser. Relays hold frames in memory only long enough to forward them.

We do not record, archive or store screen recordings or screenshots as part of normal operation. If we ever add an opt-in recording feature, it will be clearly labelled and off by default.

4.Why we process it (legal bases)

  • Contract performance — running your account, connecting your devices, taking payment.
  • Legitimate interests — securing the service, preventing abuse and fraud, debugging, and protecting our infrastructure.
  • Legal obligation — retaining invoices and tax records.
  • Consent — non-essential cookies and the rental waitlist. Withdrawable at any time.

5.Processors we use

  • Vercel — application hosting and edge/serverless request logs.
  • Supabase (PostgreSQL) — the application database.
  • Stripe — payments, invoicing and the customer portal. Stripe is an independent controller for payment data.
  • Resend — transactional email delivery (verification, password reset, billing, referral notices).
  • Tailscale — the VPN mesh used for remote touch when a phone is away from our Mac.
  • Relay hosts — our own EU / US / Asia relay servers that forward streams.

Some processors are outside the EEA. Transfers rely on Standard Contractual Clauses or an equivalent safeguard.

6.What we do not do

  • We do not sell personal data.
  • We do not run advertising networks or share data with ad-tech.
  • We do not read the content of your device screens except when you ask us to help debug and you share it with us.
  • We do not use your data to train machine-learning models.

7.Retention

  • Account and device records: for the life of the account, then deleted within 90 days of closure.
  • Pairing records and VPN metadata: until you delete the device or ask us to purge them.
  • Invoices and payment records: as long as tax law requires (typically 7–10 years).
  • Operational logs: short-lived, typically 30 days.
  • Verification and reset tokens: until used or expired.
  • Waitlist emails: until the rental product launches or you ask to be removed.

8.Security

  • Passwords are hashed with bcrypt; sessions are signed, HTTP-only cookies.
  • All traffic is TLS-encrypted; relay tokens are short-lived and scoped to one device.
  • Pairing records and access keys are stored as secrets and only used to reach the device they belong to.
  • Cross-account admin access is limited to a small allowlist and every impersonation is written to an audit log.

No system is perfectly secure. If we discover a breach affecting your data, we notify you and the relevant supervisory authority as required by law.

9.Your rights

Subject to local law you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Email privacy@fleetdeck.co and we will respond within 30 days. You may also complain to your local data-protection authority.

You can delete individual devices — including their pairing records — from the dashboard at any time.

10.Children

FleetDeck is for business and personal device management by adults. It is not directed at children and we do not knowingly collect their data.

11.Cookies

Session cookies are strictly necessary to keep you signed in. Everything else requires your consent. Details are in the Cookie Policy.

12.Changes

We will post updates here and, for material changes, notify you by email. The “last updated” date above always reflects the current version.

Terms of ServicePrivacy PolicyCookie Policy← Back to FleetDeck